Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\svihotq] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\svihotq] 'ImagePath' = 'C:\system16\svnsrq32.exe'
- C:\system16\svnsrq32.exe
- C:\system16\svnsrq64.exe
- C:\system16\ssleay32.dll
- C:\system16\libeay32.dll
- C:\system16\7z.dll
- %TEMP%\WER8fb6.dir00\svnsrq32.exe.mdmp
- %TEMP%\WER8fb6.dir00\svnsrq32.exe.hdmp
- %TEMP%\WER8fb6.dir00\appcompat.txt
- %TEMP%\WER8fb6.dir00\manifest.txt
- C:\system16\ssleay32.dll в C:\system16\ssleay32.dll812
- C:\system16\libeay32.dll в C:\system16\libeay32.dll729
- C:\system16\7z.dll в C:\system16\7z.dll781
- C:\system16\ssleay32.dll
- C:\system16\libeay32.dll
- C:\system16\7z.dll
- '31.##4.234.48':80
- http://31.##4.234.48/index.php?&1###########################
- http://31.##4.234.48/index.php?&1####################
- http://31.##4.234.48/index.php?&1#####
- 'C:\system16\svnsrq32.exe'